#access-code
Relapse enables PS5 jailbreaking on firmware up to 13.6 by exploiting a WebKit vulnerability to gain kernel write access and run arbitrary code efficiently.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 30, 2026 at 6:56 PM
ANTHROPIC EXPANDS CLAUDE AVAILABILITY: CLAUDE CODE CLI & CLAUDE FOR MICROSOFT 365 ENTER EARLY ACCESS; CLAUDE FOR GOVERNMENT NOW GENERALLY AVAILABLE
September 30, 2026 at 5:35 PM
First PATREON early access view is out for Members🧡

Join now with code: 9E096 for 20% OFF first month!

🔗link below⤵️
September 30, 2026 at 5:34 PM
Anthropic: Claude for Government is now generally available; Claude Code CLI and Claude for Microsoft 365 also now available in early access
September 30, 2026 at 5:33 PM
This election’s voter information was mailed in French only. English information is available online through a QR code. An election should be the easiest possible moment to understand your rights. “Find a phone and scan this” is an absurd answer to a language-access problem.
September 30, 2026 at 5:33 PM
Ends : September 30th 2026

Enter this Bosh Draws raffle to win a 5★ Dubai Holiday - 5 Nights • 2 Adults • Emirates Flights Included

£4.99 Per Ticket

Save 40% on ALL ticket bundles.

Use code

BOSH40
WIN A 5-NIGHT LUXURY DUBAI ESCAPE FOR 2 – THE WESTIN, EMIRATES FLIGHTS & WATERPARK ACCESS! | Bosh Draws
Swap the everyday for Dubai sunshine, five-star beachfront luxury and days beside the pool! One lucky winner and their guest will enjoy 5 nights at The Westin Dubai Mina Seyahi Beach Resort &...
boshdraws.com
September 30, 2026 at 5:32 PM
Ends : September 30th 2026

Enter this Bosh Draws raffle to win a 5★ Dubai Holiday - 5 Nights • 2 Adults • Emirates Flights Included

£4.99 Per Ticket

Save 40% on ALL ticket bundles.

Use code

BOSH40
WIN A 5-NIGHT LUXURY DUBAI ESCAPE FOR 2 – THE WESTIN, EMIRATES FLIGHTS & WATERPARK ACCESS! | Bosh Draws
Swap the everyday for Dubai sunshine, five-star beachfront luxury and days beside the pool! One lucky winner and their guest will enjoy 5 nights at The Westin Dubai Mina Seyahi Beach Resort &...
boshdraws.com
September 30, 2026 at 5:32 PM
WatchGuard fixed 15 Fireware OS flaws, including CVE-2026-86131, a critical code injection bug that could let a remote attacker run commands as root on Firebox appliances. #WatchGuard #FirewareOS #Firebox
WatchGuard Patches Critical Fireware OS Code Injection Vulnerability
WatchGuard released fixes for 15 vulnerabilities in Fireware OS, including CVE-2026-86131, a critical RCE flaw that could let a remote attacker controlling a VPN server execute commands as root on a Firebox appliance. The update also addresses multiple high-severity issues and recent Access Point flaws in WatchGuard AP, with no known...
www.hendryadrian.com
September 30, 2026 at 5:30 PM
CVE-2026-47599 - NVIDIA GPU Display Driver Improper Memory Access Permission Handling
CVE ID : CVE-2026-47599

Published : Sept. 30, 2026, 4:17 p.m. | 42 minutes ago

Description : NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel modul...
CVE-2026-47599 - NVIDIA GPU Display Driver Improper Memory Access Permission Handling
NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module where an unprivileged local user could cause improper preservation of memory access permissions during DMA mapping. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and …
cvefeed.io
September 30, 2026 at 5:16 PM
A document by Netzpolitik reveals that German police are sneakily abusing the linked devices feature in messengers to access the messages of suspects using encrypted messengers like Signal without needing to crack the encryption.

German customs officials have been using the web client of […]
German Police Are Using Linked Devices to Read Signal Messages Without Cracking the Encryption
A document by Netzpolitik reveals that German police are sneakily abusing the linked devices feature in messengers to access the messages of suspects using encrypted messengers like Signal without needing to crack the encryption. German customs officials have been using the web client of different messengers like Telegram and WhatsApp and logging in with the suspect's phone number. The unencrypted SMS code that's sent for authentication can then be intercepted by law enforcement to log in to the account. Sometimes authorities need physical access to log in, which is a slightly higher barrier. But once they're able to authenticate, they can have access to your messages as long as you don't notice their sessions logged in to your account. The document states that the German customs agency has been testing messenger surveillance since the end of 2023, and it has led to success in criminal investigations. This type of surveillance became an official, permanent strategy available to all agents since August 2025. The messengers affected include WhatsApp, Telegram, Threema, and Signal. Earlier this year, a Signal phishing attack was carried out by what is believed to be a state actor trying to gain access to Signal accounts. The attack asked for you to respond with your Signal SMS message, which was triggered by the attacker trying to log in with your phone number. If you text them the code, all your messages from then on are now monitored. Signal is often touted as a highly secure messenger. Indeed, it boasts some of the most robust encryption messengers have to offer, and other messengers like WhatsApp even use the Signal protocol for their encryption. But their reliance on SMS for account authentication is clearly a massive security issue. Signal recently launched phone numberless accounts in beta on Android, allowing you to sign up without ever giving your number to Signal while paying a small one-time fee. Your account will be protected by a new secure Account ID and Recovery key that you can save in your password manager, which you will need in order to log in. They also announced future support for passkeys. Passkeys are phishing-resistant by design and not available outside of your password manager, so you can't be tricked into typing it in during a phishing attempt. Telegram added passkey support in 2025, although you have to go out of your way to enable it. WhatsApp now supports passkeys as well, so you can secure your account that way. It's also a good idea to occasionally check your active sessions/devices in the settings in your messenger of choice and remove any devices you don't recognize.
www.privacyguides.org
September 30, 2026 at 4:52 PM
The doors can be opened with a code the flight crew has, in case of pilot incapacitation. The code is time delayed and the pilots can manually deny access to avoid a hijacker from forcing crew to use the code. If the pilot doesn't manually deny entry the door will unlock after a set time.
September 30, 2026 at 4:34 PM
Rogue OpenAI Agents Access Government Data and Security Systems (30.9.2026) #machinelearning #ai
Rogue OpenAI Agents Access Government Data and Security Systems (30.9.2026)
OpenAI’s dirty deeds Down Under included security bypass attempts, using exposed keys, source code siphon https://www.theregister.com/ai-and-ml/2026/09/29/openais-dirty-deeds-down-under-included-security-bypass-attempts-using-exposed-keys-source-code-siphon/5299666 OpenAI agents accessed Census, SEC data and tried to hack Education website https://www.nextgov.com/cybersecurity/2026/09/openai-says-its-advanced-models-may-have-gone-after-government-websites/416250/ OpenAI expands review of model behavior after more rogue agent incidents emerge https://www.cnbc.com/2026/09/26/openai-agent-model-behavior-review.html OpenAI agents accessed government websites, as review of rogue AI expands https://qz.com/openai-agents-government-websites-misalignment-review-092626 Rogue OpenAI agents accessed US government websites https://www.politico.com/news/2026/09/25/rogue-openai-agents-accessed-us-government-websites-01094035 OpenAI pauses training a second time as rogue agents hit U.S. government websites https://www.investing.com/news/stock-market-news/openai-pauses-training-a-second-time-as-rogue-agents-hit-us-government-websites-4918960
dlvr.it
September 30, 2026 at 4:21 PM
If we can enshrine 12-foot fire lanes in the fire code and Streets Illustrated, it will be a boon for safe streets.
September 30, 2026 at 4:07 PM
I asked myself the same question: perhaps trained personnel with an access code; perhaps the pilot under attack managed to open the door for the crew or passengers; perhaps there was a struggle over the locking switch—there are many possibilities, I have no idea.

But most likely no miracle.
September 30, 2026 at 4:01 PM
At its core, Zip Code Wilmington is a network of students, alumni, instructors and employer partners all pulling toward the same goal: more people with real access to careers in technology.

As a community, we are stronger together.

#ZipCodeWilmington #DelawareWorks
September 30, 2026 at 4:00 PM
(2/2) Trainees registering for the conference also get access to the trainee half-day, organized by our own NYU trainees

Register here!: www.eventbrite.com/e/memory-hub...
September 30, 2026 at 3:55 PM
Seems they do have a code and if no answer they get access, but pilot can override. Which wouldnt have helped in the Germanwings situation, but may have gotten them access here. Very, very lucky it would seem.
September 30, 2026 at 3:54 PM
Every LLM framework rebuilt the same tool object
If you give an LLM access to your code, you write tools. A tool is a function plus what a model needs to call it: a name, a description, and a schema for the arguments. Then you write the same tools again. The first version uses the AI SDK's `tool()`. The project adds an MCP server, so the tools are rewritten for `registerTool`. Another team uses Mastra, and the tools are written a third time with `createTool`. The functions stay the same. Only the wrapper changes. Each wrapper is also tied to its framework. `tool()` comes from the `ai` package, `createTool` from `@mastra/core`, and `registerTool` is a method of the MCP SDK's `McpServer`. A library that wants to ship tools has to choose one framework, and everyone who uses the library installs it. Without the framework, a tool is a function that describes itself: the function, plus a name, a description, and schemas for its input and output. That is enough for a model to decide when and how to call it. It is also enough to generate docs, build a form, or add a CLI command. Written as a plain object with those fields, a tool belongs to your code. Moving it to another framework takes a small adapter instead of a rewrite. The hardest part of that object is the schemas, and the schemas are already standardized. ## What is Standard Schema? Standard Schema is a TypeScript interface for validation libraries, designed by the creators of Zod, Valibot, and ArkType. Code that accepts a Standard Schema works with a schema from any library that implements it, with no adapter per library. The whole interface is one property, `~standard`. Trimmed to its fields: interface StandardSchemaV1<Input = unknown, Output = Input> { readonly '~standard': { readonly version: 1; readonly vendor: string; readonly validate: (value: unknown) => Result<Output> | Promise<Result<Output>>; readonly types?: { readonly input: Input; readonly output: Output }; }; } // Result<Output> is { value: Output } on success and { issues: Issue[] } on failure. Validation code is the same for every library: const result = await schema['~standard'].validate(data); if (result.issues) throw new Error(result.issues.map((issue) => issue.message).join('; ')); const value = result.value; // typed as the schema's output More than 30 libraries implement the spec, including Zod, Valibot, ArkType, yup, and joi. More than 60 tools accept it, including tRPC, TanStack Form and Router, Hono, Elysia, oRPC, and React Hook Form. The spec is types only. The `@standard-schema/spec` package has no runtime code, and a library may copy the interface instead of depending on the package. ## What is Standard JSON Schema? Validation is half of what a tool needs from its schemas. The other half is JSON Schema: a model needs a JSON Schema of the arguments before it can call a tool. Standard JSON Schema is a companion spec by the same authors. It adds a JSON Schema converter under the same `~standard` property: schema['~standard'].jsonSchema.input({ target: 'draft-2020-12' }); schema['~standard'].jsonSchema.output({ target: 'openapi-3.0' }); `target` selects the JSON Schema dialect, because consumers need different ones. OpenAI, Anthropic, and MCP take JSON Schema draft 2020-12. Gemini's `parameters` field takes the OpenAPI 3.0 format. `input` and `output` are separate because a schema can transform values. A schema that accepts `"42"` and returns `42` has one JSON Schema for its input and another for its output. The two specs are independent, and an object can implement either or both. Zod 4.2+ and ArkType 2.1.28+ schemas implement both. In Valibot 1.2+, `toStandardJsonSchema()` from `@valibot/to-json-schema` wraps a schema so that it implements both. ## What is Standard Tool? Once the schemas validate and emit JSON Schema on their own, the rest of a tool is a name, a description, and a function. That part has no standard, so every framework defines its own object for it. `StandardToolV0` is a proposal for that object: import type { StandardSchemaV1, StandardJSONSchemaV1 } from '@standard-schema/spec'; interface StandardToolV0< Input = unknown, Output = unknown, FormattedOutput = Output, Context = unknown, > { name: string; title?: string; description: string; inputSchema?: StandardSchemaV1<Input, unknown> & StandardJSONSchemaV1<Input, unknown>; outputSchema?: StandardSchemaV1<unknown, Output> & StandardJSONSchemaV1<unknown, Output>; meta?: Record<string, unknown>; execute(input: Input, context?: Context): FormattedOutput | Promise<FormattedOutput>; } * `name` is the identifier the model uses to call the tool. * `description` tells the model what the tool does and when to use it. * `title` is an optional label for people, which MCP clients can show in tool lists. * `inputSchema` and `outputSchema` must implement both specs, so each one validates and emits JSON Schema. `Input` is the input side of the input schema, and `Output` is the output side of the output schema, so schemas that transform values fit. * `meta` is static data about the tool, such as `{ destructive: true }`. Consumers read it, and `execute` never sees it. * `execute` runs the tool. Its optional second argument, `context`, carries per-call data such as a locale or an auth token. `context` is not validated and does not appear in the JSON Schema. * `FormattedOutput` is what `execute` returns when a wrapper changes the result, for example to return errors as data. It defaults to `Output`. Like the two specs, `StandardToolV0` is a type. Any object with these fields conforms: import { z } from 'zod'; // or ArkType, or Valibot import type { StandardToolV0 } from 'standard-tool'; export const getWeather: StandardToolV0<{ city: string }, { tempC: number }> = { name: 'get_weather', description: 'Current temperature for a city', inputSchema: z.object({ city: z.string() }), outputSchema: z.object({ tempC: z.number() }), execute: async ({ city }) => ({ tempC: await fetchTemperature(city) }), }; The import is types only, and you can paste the interface into your project instead. The `standard-tool` package also contains an optional reference implementation of about 90 lines. `standardTool()` wraps a definition so that `execute` validates the input before your function runs and the output after it, and throws `StandardToolValidationError` on a mismatch. `withFormattedOutput()` catches errors and returns them as data, so a model can read what went wrong. ## How it compares Every framework has this object. The differences are mostly names and argument positions: | Package | Identifier | Input schema | Output schema | Function ---|---|---|---|---|--- AI SDK | `ai` | key in the tools object | `inputSchema` | `outputSchema` | `execute` Mastra | `@mastra/core` | `id` | `inputSchema` | `outputSchema` | `execute` Genkit | `genkit` | `name` | `inputSchema` | `outputSchema` | 2nd argument of `defineTool` LangChain | `@langchain/core` | `name` | `schema` | none | 1st argument of `tool` MCP SDK | `@modelcontextprotocol/sdk` | 1st argument of `registerTool` | `inputSchema` | `outputSchema` | 3rd argument of `registerTool` `StandardToolV0` | none, it is a type | `name` | `inputSchema` | `outputSchema` | `execute` What each framework accepts as a schema differs more: * **AI SDK:** Standard Schema, Zod, or JSON Schema * **Mastra:** Standard Schema with Standard JSON Schema, Zod, or JSON Schema * **Genkit:** Zod or JSON Schema * **LangChain:** Zod or JSON Schema * **MCP SDK:** Zod only Checked against `ai` 7.0, `@mastra/core` 1.72, `genkit` 1.42, `@langchain/core` 1.2, and `@modelcontextprotocol/sdk` 1.31. The objects look alike, but they are not interchangeable, and each one needs its framework's package. Moving a tool to another framework means rewriting its wrapper. Reusing a tool written for another framework means installing that framework. This matters even with one framework. A framework's tool object is made for that framework. A plain object can also be called from a script or a test, read by a docs generator, or exported from a library whose users don't install your framework. ## How it can be used The object has more than one reader. A model is one of them. **Call it.** `execute` is a function: const { tempC } = await getWeather.execute({ city: 'Paris' }); **Give it to a model.** `name`, `description`, and the JSON Schema from `inputSchema` become the provider's tool definition. When the model calls the tool, its arguments go to `execute`. The next section shows this per provider. **Read it.** The fields are enough for reference docs, a list of tools in a prompt, a form built from `inputSchema`, or a CLI command: function describeTools(tools: StandardToolV0[]) { return tools.map((tool) => ({ name: tool.name, description: tool.description, input: tool.inputSchema?.['~standard'].jsonSchema.input({ target: 'draft-2020-12' }), output: tool.outputSchema?.['~standard'].jsonSchema.output({ target: 'draft-2020-12' }), })); } **Ship it from a library.** A library can export tools as ordinary values: export const getOrders: StandardToolV0<{ userId: string }, Order[]> = { name: 'get_orders', description: "List a user's orders", inputSchema: z.object({ userId: z.string() }), execute: ({ userId }) => api.get(`/orders/${userId}`), }; The library's users can run the tool, document it, or give it to a model, and the library depends on no AI framework. **Reuse RPC procedures.** A tRPC or oRPC procedure already has input and output schemas and a handler. If its schemas implement Standard JSON Schema, they become the tool's schemas, and `execute` calls the procedure through the framework's server-side caller. Example with tRPC. ## Adapting to frameworks and models Every integration does two things. It builds the provider's tool definition from `name`, `description`, and the JSON Schema. Then, when the model calls the tool, it runs `execute` and sends the result back. Only the field names and the JSON Schema dialect change between providers: Consumer | Schema field | `target` | Result goes back as ---|---|---|--- OpenAI Responses API | `parameters` | `draft-2020-12` | a `function_call_output` item Anthropic | `input_schema` | `draft-2020-12` | a `tool_result` block Gemini | `parameters` | `openapi-3.0` | a `functionResponse` part MCP | `inputSchema` in the tool descriptor | `draft-2020-12` | `{ content, structuredContent?, isError? }` AI SDK | `inputSchema`, which takes the Standard Schema as is | none | the SDK runs the loop Anthropic, both halves: import type Anthropic from '@anthropic-ai/sdk'; import type { StandardToolV0 } from 'standard-tool'; export function toAnthropicTool(tool: StandardToolV0): Anthropic.Tool { const schema = tool.inputSchema?.['~standard'].jsonSchema.input({ target: 'draft-2020-12' }); return { name: tool.name, description: tool.description, input_schema: (schema ?? { type: 'object', properties: {} }) as Anthropic.Tool.InputSchema, }; } export async function runToolUse( tools: StandardToolV0[], block: Anthropic.ToolUseBlock, ): Promise<Anthropic.ToolResultBlockParam> { try { const tool = tools.find((t) => t.name === block.name); if (!tool) throw new Error(`Unknown tool: ${block.name}`); const result = await tool.execute(block.input); return { type: 'tool_result', tool_use_id: block.id, content: JSON.stringify(result) }; } catch (error) { const message = error instanceof Error ? error.message : String(error); return { type: 'tool_result', tool_use_id: block.id, content: message, is_error: true }; } } `execute` receives the model's arguments unchecked. A tool made with `standardTool()` validates them against `inputSchema`; a hand-written tool has to check them itself. For another provider, change the field and the `target` from the table. Each adapter is written once, and adding a provider changes no tools. ## Conclusion A tool written as a function that describes itself belongs to your code. You can call it, test it, document it, and give it to any model or framework, and it stays the same object. `StandardToolV0` is one TypeScript interface with no runtime. It is a proposal. The `V0` shape is frozen, so feedback that changes it goes into a new interface, `StandardToolV1`. The spec, the reference implementation, and the reasoning behind them are at standard-tool.js.org. The obvious objection is XKCD 927: until other projects produce or read this shape, it is one more competing format. Standard Schema shows that a small interface with no runtime can be adopted widely, but it started with the authors of Zod, Valibot, and ArkType behind it. This proposal has one maintainer and no such backing. The most useful feedback now is where the shape is wrong: open an issue.
dev.to
September 30, 2026 at 3:52 PM
Reading about concerns over academics being used to spy on AI research www.reuters.com/world/uk/uk-... Which would be slightly ironic in our case... Our papers are on arXiv. Our code is on GitHub. Our slides are online. Espionage seems like an unnecessarily complicated way to access our research.
UK accuses China of using academics to spy on AI and other tech research
Britain's MI5 spy agency issued an unprecedented alert on Wednesday to ​warn that a Chinese organisation was involved in funding academic research into topics such as AI on behalf ‌of Beijing's state ...
www.reuters.com
September 30, 2026 at 3:39 PM
Industry? Open doors for outlets; give code, give access. Give indies a shot & be surprised by how much more soulful their coverage is than a big outlet where everyone is overworked to the bone
September 30, 2026 at 3:36 PM
I think a bit f code with no Internet access would probably be fine. But I'd watch it like a fucking hawk!
September 30, 2026 at 3:28 PM
!

Also ‘run some tools on your end’ presumably with access to production code seems a bit… insecure.

But I’m no tech security expert, what do I know about running almost certainly ‘vibe coded’ tools on my tech assets.
September 30, 2026 at 3:16 PM
TeamViewer released urgent patches for high-severity flaws in Full Client and Host for Windows, Linux, and macOS, including access control bypass that could enable RCE. Update to version 15.82. #TeamViewer #CVE202692370 #Windows
TeamViewer Urges Users To Patch Severe Flaws “as Soon As Possible”
TeamViewer warned users to urgently patch multiple high-severity vulnerabilities in TeamViewer Full Client and Host software for Windows, Linux, and macOS, including a remote session access control bypass that could lead to remote code execution. The company said it is not aware of active exploitation, but urged immediate updating to TeamViewer version 15.82 to reduce the risk of unauthorized access and privilege escalation. #TeamViewer #CVE-2026-92370 #CVE-2026-19743 #CVE-2026-92368 #CVE-2026-92369 #CVE-2026-92371 #Winnti #MidnightBlizzard
www.hendryadrian.com
September 30, 2026 at 3:15 PM